{5bfccbb2-73ab-446d-b1db-c717279ae8fc}

Refog Inc.

The file {5bfccbb2-73ab-446d-b1db-c717279ae8fc} by Refog has been detected as a potentially unwanted program by 6 anti-malware scanners.
Publisher:
Refog Inc.  (signed and verified)

Version:
8.3.0.2199

MD5:
fac806b22bce2d3523c66c70b8927be3

SHA-1:
c12bbecb3fab5093ea256673433a3321c75aa531

SHA-256:
9384e879428c7b02e3f6c0812992511acf0e4c40a2d85f3e03cf6c0cc0d4e419

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 12:21:41 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.Win32.Refog
4.0.3.15918

Comodo Security
UnclassifiedMalware
22115

ESET NOD32
Win32/KeyLogger.Refog (variant)
9.11627

Reason Heuristics
PUP.Refog (M)
15.9.18.16

Trend Micro House Call
Suspicious_GEN.F47V0418
7.2.261

VIPRE Antivirus
Refog Inc.
40232

File size:
1.4 MB (1,499,448 bytes)

Product version:
8.3.0.2199

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/4/2013 1:00:00 AM

Valid to:
3/6/2016 12:59:59 AM

Subject:
CN=Refog Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Refog Inc., L=Alexandria, S=Virginia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7FF3DAF8E8B0D4A05A226B85F1054E87

File PE Metadata
Compilation timestamp:
4/6/2015 1:17:32 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.25

CTPH (ssdeep):
24576:jYkHGqHO6pTADZVjLXaEfBeSOwXwQcfd5TwevnABMtjxZ/ijztMoxr6+:jLHxdQZZ5fYSOKBsjxZ/ijzqoxrv

Entry address:
0x145728

Entry point:
55, 8B, EC, B9, 0B, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, A1, 8C, AB, 54, 00, C6, 00, 01, B8, D4, D0, 53, 00, E8, 3F, 59, EC, FF, 33, C0, 55, 68, D8, 5B, 54, 00, 64, FF, 30, 64, 89, 20, 33, C0, 55, 68, A9, 5B, 54, 00, 64, FF, 30, 64, 89, 20, C6, 05, 08, 04, 55, 00, 00, C6, 05, 09, 04, 55, 00, 00, C6, 05, 18, 04, 55, 00, 01, E8, 29, F1, EB, FF, A3, 10, 04, 55, 00, 83, 3D, 10, 04, 55, 00, 00, 0F, 8E, DA, 00, 00, 00, 68, FC, 03, 55, 00, 8D, 55, E8, B8, 01, 00, 00, 00, E8, 65, F1, EB, FF, 8B...
 
[+]

Entropy:
6.5001

Developed / compiled with:
Microsoft Visual C++

Code size:
1.3 MB (1,328,128 bytes)

Remove {5bfccbb2-73ab-446d-b1db-c717279ae8fc} - Powered by Reason Core Security